Patentable/Patents/US-12710974-B2
US-12710974-B2

Secure mapping of process address space identifiers for computing environments implementing input/output virtualization

PublishedAugust 18, 2026
Assigneenot available in USPTO data we have
Technical Abstract

A processor includes a virtual machine manager (VMM) configured to map a guest process address space identifier (PASID) associated with a virtual machine (VM) to a host PASID associated with a host machine of the VM. The processor further includes a processor core configured to maintain, responsive to the guest PASID being mapped to the host PASID, an entry in a PASID reverse mapping table (PMP) including one or more security attributes associated with the host PASID.

Patent Claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

mapping, by a virtual machine manager, a guest process address space identifier (PASID) associated with a virtual machine (VM) to a host PASID associated with a host machine of the VM; and responsive to the mapping, maintaining, by a security module of a processor, an entry in a PASID reverse mapping table (PMP) indexed by the host PASID, the entry including one or more security attributes associated with the host PASID. . A method comprising:

2

claim 1 storing, as a security attribute of the one or more security attributes, the guest PASID in a field of the entry; and storing, as a second security attribute of the one or more security attributes, a guest identifier associated with the VM in a second field of the entry. . The method of, wherein maintaining the entry in the PMP comprises:

3

claim 2 setting, as a third security attribute of the one or more security attributes, an indicator in a third field of the entry indicating that the VM has not validated the guest PASID and the guest identifier stored in the entry. . The method of, wherein maintaining the entry in the PMP comprises:

4

claim 1 receiving a PMP validation instruction from the VM including a guest PASID; translating the guest PASID included in the PMP validation instruction to a host PASID; determining that the entry in the PMP corresponds to the host PASID associated with the translated guest PASID; and responsive to the one or more security attributes in the entry indicating that a guest PASID stored in the entry matches the translated guest PASID and a guest identifier stored in the entry corresponds to a guest identifier of the VM, setting an indicator in the entry indicating that the VM has validated the guest PASID and the guest identifier stored in the entry. . The method of, further comprising:

5

claim 1 responsive to receiving a request from the VM to access a virtual device, translating a guest PASID included in the request to a host PASID; identifying the entry in the PMP based on the host PASID associated with the translated guest PASID; and responsive to the one or more security attributes satisfying at least one specified condition, allowing the access to the virtual device by the VM. . The method of, further comprising:

6

claim 5 . The method of, wherein the at least one specified condition includes a guest PASID stored in the entry matching the translated guest PASID and a guest identifier stored in the entry matching a guest identifier of the VM.

7

claim 6 . The method of, wherein the at least one specified condition further includes an indication that the VM has previously validated the guest PASID and the guest identifier stored in the entry.

8

claim 1 responsive to receiving a request from the VM to access a virtual device, translating a guest PASID included in the request to a host PASID; identifying an entry in the PMP based on the host PASID associated with the translated guest PASID; and a guest PASID stored in the identified entry and a guest identifier stored in the identified entry failing to match the translated guest PASID and a guest identifier of the VM, or the identified entry including an indication that the VM has not previously validated the guest PASID and the guest identifier stored in the identified entry. preventing the access to the virtual device responsive to at least one of: . The method of, further comprising:

9

in response to receiving, from a virtual machine (VM) device, a request to access a virtual device, translating a guest process address space identifier (PASID) of the VM to a host PASID associated with a host machine; and preventing the access to the virtual device responsive to identifying that an entry in a PASID reverse mapping table (PMP) indexed by the host PASID fails to satisfy one or more conditions. . A method comprising:

10

claim 9 determining that a guest PASID stored in the entry fails to match the translated guest PASID; or determining a guest identifier stored in the entry fails to match a guest identifier of the VM. . The method of, wherein the preventing of the access comprises at least one of:

11

claim 9 . The method of, wherein the preventing of the access comprises determining that the entry comprises an indication that the VM has not validated at least one of a guest PASID stored in the entry and a guest identifier stored in the entry.

12

claim 9 determining that a guest PASID stored in the entry matches the translated guest PASID; and determining a guest identifier stored in the entry matches a guest identifier of the VM. . The method of, further comprising allowing the access of the virtual device responsive to:

13

claim 9 . The method of, further comprising allowing the access of the virtual device responsive to determining that the entry comprises an indication that the VM has validated at least one of a guest PASID stored in the entry and a guest identifier stored in the entry.

14

an executable virtual machine manager (VMM) configured to map a guest process address space identifier (PASID) associated with a virtual machine (VM) to a host PASID associated with a host machine of the VM; and a processor core configured to maintain, responsive to the guest PASID being mapped to the host PASID, an entry in a PASID reverse mapping table (PMP) indexed by the host PASID, the entry including one or more security attributes associated with the host PASID. . A processor comprising:

15

claim 14 storing, as a security attribute of the one or more security attributes, the guest PASID in a field of the entry; and storing, as a second security attribute of the one or more security attributes, a guest identifier associated with the VM in a second field of the entry. . The processor of, wherein the processor core is configured to maintain the entry in the PMP by:

16

claim 15 setting, as a third security attribute of the one or more security attributes, an indicator in a third field of the entry indicating that the VM has not validated the guest PASID and the guest identifier stored in the entry. . The processor of, wherein the processor core is configured to maintain the entry in the PMP by:

17

claim 14 receive a PMP validation instruction from the VM including a guest PASID; translate the guest PASID included in the PMP validation instruction to a host PASID; determine that the entry in the PMP corresponds to the host PASID associated with the translated guest PASID; and responsive to the one or more security attributes in the entry indicating that a guest PASID stored in the entry matches the translated guest PASID and a guest identifier stored in the entry corresponds to a guest identifier of the VM, set an indicator in the entry indicating that the VM has validated the guest PASID and the guest identifier stored in the entry. . The processor of, wherein the processor core is further configured to:

18

claim 14 responsive to a request being received from the VM to access a virtual device, translate a guest PASID included in the request to a host PASID; identify the entry in the PMP based on the host PASID associated with the translated guest PASID; and responsive to the one or more security attributes satisfying at least one specified condition, allowing the access to the virtual device by the VM. . The processor of, wherein the processor core is further configured to:

19

claim 18 a guest PASID stored in the entry matching the translated guest PASID and a guest identifier stored in the entry matching a guest identifier of the VM; or an indication that the VM has previously validated the guest PASID and the guest identifier stored in the entry. . The processor of, wherein the at least one specified condition includes at least one of:

20

claim 14 responsive to a request being received from the VM to access a virtual device, translate a guest PASID included in the request to a host PASID; identify an entry in the PMP based on the host PASID associated with the translated guest PASID; and a guest PASID stored in the identified entry and a guest identifier stored in the identified entry failing to match the translated guest PASID and a guest identifier of the VM, or the identified entry including an indication that the VM has not previously validated the guest PASID and the guest identifier stored in the identified entry. prevent the access to the virtual device responsive to at least one of: . The processor of, wherein the processor is further configured to:

Detailed Description

Complete technical specification and implementation details from the patent document.

Processing systems (e.g., servers) often employ virtualized execution environments to combine and scale physical and logical resources of the processing system. For example, processing systems execute virtual machines (guests), which are software entities that emulate or otherwise interface with the hardware of the processing systems to provide support for executing software programs. A virtual machine can use hardware elements (e.g., processors, memories, network interfaces, etc.) in a processing system to provide support for running one or more instances of operating systems, referred to as guest operating systems. The guest operating systems in turn provide support for executing other software programs, such as applications and databases. A virtual machine manager or monitor (e.g., a hypervisor) controls the scheduling of the different virtual machines for execution and provides an interface between the virtual machines and the server hardware, so that each VM is able to operate as if that VM were executing on its own dedicated hardware. In another example, processing systems virtualize one or more of their input/output devices, such as controllers (e.g., bus, interconnect, and/or fabric controllers, network interface controllers, etc.), processors/accelerators (e.g., graphics processors, cryptographic accelerators, compression accelerators), and any other resources that can be addressed in the processing systems. Virtualization of an input/output device allows the physical device to appear as multiple physical devices to host machine or virtual machine.

Various techniques can be implemented by a processing system for virtualizing input/output (I/O) devices. One example, of an I/O virtualization technique is single-root I/O virtualization (SR-IOV), which enables multiple virtual machines (also referred to herein as guests or VMs) to share Peripheral Component Interconnect Express (PCIe) hardware resources under a single-node system (e.g., single root complex). For example, an SR-IOV device allows a physical device, such as a network interface controller (NIC), to appear as multiple NICs to a VM or host machine. Accordingly, multiple VMs at a host machine are able to share a single PCIe device. In an SR-IOV environment, the hypervisor (also referred to as a virtual machine manager or monitor (VMM)) maps one or more logical interfaces (i.e., virtual functions) to a VM, where each logical interface appears as a single input/output device to the host operating system (OS). However, the number of virtualized instances (e.g., virtual functions) of a given hardware type, such as an NIC or bus, is limited. For example, an NIC is limited by hardware constraints with respect to the number of virtual functions that it can support. As such, SR-IOV limits the number of virtual functions for an input/output device, which also limits the number of VMs that can utilize the virtual functions.

Scalable I/O Virtualization (SIOV) attempts to overcome the scalability and other issues associated with SR-IOV. SIOV is a PCIe-based virtualization technique that provides for scalable sharing across virtualized execution environments of I/O devices. Unlike the coarse-grained device partitioning approach of SR-IOV to create multiple virtual functions on device, SIOV enables software to flexibly compose virtual devices utilizing the hardware-assists for device sharing at finer granularity. Performance critical operations on the composed virtual device are mapped directly to the underlying device hardware, while non-critical operations are emulated through device-specific composition software in the host.

SIOV scales device interactions by implementing shared work queues (SWQs) and a type of memory access over PCIe referred to as deferrable memory writes. For example, an SIOV capable device is configured to group its resources into multiple isolated assignable device interfaces (ADIs), which form the unit of assignment and isolation for devices to form virtual devices. ADIs are associated with SWQs for work submission, which are interfaces that can be used simultaneously by different VMs. Stated differently, an SWQ allows multiple VMs to submit work requests to the same ADI. A process of a VM submits work requests to an SWQ using deferrable memory writes (DMWrs). A DMWr is a write that can temporarily fail due to unavailability of the underlying resource. Such a failure indicates that the process should re-attempt access to the SWQ. When a process within a VM writes to the registers of an SWQ for submitting work requests/descriptors to the ADI, the process uses an instruction to create a DMWr to that register. That is, the instruction used by the process atomically submits a work descriptor to the SWQ. More generally, the instruction is an “enqueue command” for writing commands to “enqueue registers”, which are special device registers accessed using memory-mapped I/O (MMIO). Examples of this instruction include Enqueue Command (ENQCMD) and Enqueue Command Supervisor (ENQCMDS).

In SIOV, clients of an ADI are identified using a process address space identifier (PASID), which is a unique identifier that isolates the process address space used by a guest (VM) OS and links the clients' accesses to their views of and access rights to memory. A PASID is used to distinguish upstream memory transactions performed for different ADIs and to convey the address space targeted by the transaction. This is in contrast with SR-IOV where a client (e.g., processes of a VM) interacts with an SR-IOV interface using an interface-specific MMIO address. In a non-virtualized environment, the OS manages the assignment of PASIDs to processes using, for example, a model specific register (MSR). This MSR allows an application address space to be associated with a PASID. The OS sets the MSR to the appropriate PASID when the scheduler context switches into the process. Then, an instruction, such as ENQCMD, uses the MSR to attach the PASID to the DMWr request to the work queue of the input/output device. However, in virtualized systems, the guest OS assigns multiple PASIDs to its processes. Therefore, the VMM virtualizes the PASID associated with a VM. That is, the VMM transparently maps the PASIDs assigned by the guest OS to real PASIDs to give the guest OS the view that it owns the entire PASID space. As part of this PASID mapping process, the VMM uses a memory data structure to point to a mapping table that maps a guest PASID to a host PASID. Therefore, when a guest process invokes an enqueue command, the PASID written by the VM process is translated automatically by the processor into a host PASID and written to the SWQ via a DMWr.

Although SIOV allows many different VMs to access a single input/output device resource without the constraints imposed by SR-IOV, SIOV is generally not designed with security or confidential computing as a priority, which can make implementing SIOV in confidential computing environments challenging. For example, the mapping from a guest PASID to a host PASID and from a host PASID to a guest context within an I/O device is trusted to the VMM in SIOV. However, the VMM is typically not considered a trusted device in a confidential computing environment because the VMM can act maliciously or introduce security risks into the environment. For example, the VMM can maliciously execute a DMWr with the PASID of a VM and gain access to an isolation domain in the SIOV environment.

Accordingly, the present disclosure describes implementations of systems and methods for securely managing PASID mapping in a confidential computing environment implementing input/output virtualization, such as SIOV or equivalent, in accordance with some implementations. As described in greater detail below, one or more techniques are implemented that allow a VMM to indirectly allocate PASIDs for a VM while not allowing the VMM arbitrary authority to change the mapping. For example, in at least some implementations, the VMM is configured to allocate a table, such as a PASID reverse map table (PMP), global to the system that is indexed by a Host PASID. When a VM process invokes an enqueue command for submitting a work request to a device interface (e.g., ADI) via an SWQ, the processor translates the guest PASID into a host PASID using one or more translation techniques. Then, the processor indexes the PMP table with the resulting host PASID. If the PMP entry associated with the host PASID includes the guest PASID and the identifier of the accessing VM process, the processor determines that the access is valid and the enqueue command proceeds. Otherwise, the processor determines that the VMM has changed the PASID mapping and enqueue command fails. For example, the processor issues an error message to one or both of the VMM or VM, which prevents the enqueue command from being processed. As such, the techniques described herein provide for the secure management of PASID mapping by a VMM and protects VMs against malicious PASID modifications.

1 FIG. 100 illustrates a processing systemthat implements secure mapping of PASIDs for virtualized computing/execution environments in accordance with some inventions. It should be understood that although one or more techniques presented herein are described with respect to scalable input/output virtualization, these techniques are applicable to any virtualization architecture, framework, or specification that implements PASID mapping for virtualized resources.

100 100 100 100 The processing systemis generally configured to execute sets of instructions (e.g., computer programs) to carry out tasks on behalf of an electronic device. Accordingly, the processing systemis part of various electronic devices in different implementations. For purposes of description, it is assumed that the processing systemis part of an electronic device that implements a confidential computing environment, such as a server. However, in other implementations, the processing systemis part of a desktop computer, laptop computer, tablet, game console, and the like.

100 102 104 106 102 104 102 104 To implement the confidential computing environment and to execute the sets of instructions and corresponding operations, the processing systemincludes a processor, a memory, and one or more input/output (I/O) devices, such as I/O device. In some implementations, the processoris a general-purpose processor, such as a central processing unit (CPU), including hardware structures configured to retrieve and execute the sets of instructions. The memoryincludes one or more memory devices configured to store and retrieve data based on commands (e.g., store and load commands) received from the processor. Accordingly, in different implementations, the memoryis random access memory (RAM), non-volatile memory (NVM), hard disc memory, and the like, or any combination thereof.

106 102 100 106 100 106 The I/O deviceis any device that can, independent of the processor, process input information, output information, or a combination thereof on behalf of the processing system. For example, in some implementations, the I/O deviceis a network interface device that processes input and output information for a network (not shown) connected to the processing system. In other implementations, the I/O deviceis a storage controller (e.g., a disc controller or non-volatile memory (NVM) storage controller), a controller associated with a user interface (e.g., a keyboard), and the like.

102 108 110 112 102 To execute the sets of instructions and corresponding operations, the processorincludes a processor core, a security module, and an input/output memory management unit (IOMMU). It will be appreciated that, in some implementations, the processorincludes additional hardware to execute instructions and to execute operations based on those instructions, such as additional processor cores, additional processing units (e.g., one or more graphics processing units), one or more controllers (e.g., memory controllers and input/output controllers), and the like.

108 108 108 108 1 FIG. The processor coreincludes one or more instruction pipelines, including a plurality of stages to execute instructions in a pipelined fashion. Thus, for example, in some implementations, an instruction pipeline of the processor coreincludes a fetch stage, a decode stage, a dispatch stage, one or more execution stages (with one or more corresponding execution units), a retire stage, and the like. The processor corealso includes, or has access to, memory structures and other hardware (not explicitly illustrated in) that support the execution of instructions. For example, in some implementations, the processor coreincludes or has access to one or more cache structures to store data used to execute the instructions.

110 102 110 102 102 100 110 104 102 102 110 102 The security moduleis a set of hardware structures generally configured to create, monitor, and maintain a secure environment for the processor. For example, in at least some implementations, the security moduleis configured to manage the boot process for the processor, initialize security-related mechanisms for the processor, and monitor the processing systemfor suspicious activity or events and implement an appropriate response. In some implementations, the security moduleincludes a microcontroller, a cryptographic coprocessor (CCP) to encrypt and decrypt data, local memory, and local registers to store, for example, cryptographic keys, and includes interfaces to interact with the memory, the I/O controller of the processor, and configuration registers of the processor. In some implementations, the security moduleincludes Environment Management Control hardware that performs environmental and security checks to ensure that the processoroperates according to specified security parameters.

110 106 114 114 106 110 110 106 106 110 114 102 106 114 In some implementations, the security modulemanages a device binding process, wherein an I/O deviceis bound to a VM (guest)by undergoing a specified security registration process. For example, in some implementations, the VMseeks to bind the I/O deviceby sending a binding request to the security module. In response, the security moduleinitiates the specified security registration process, such as by requesting authentication information (e.g., a device certificate) from the I/O deviceand verifying the authentication information (e.g., by comparing the authentication information or key information generated based on the authentication information, to one or more security keys). If the authentication information received from the I/O deviceis verified, the security moduleindicates to the VMand other components of the processor, as described further herein, that the I/O deviceis bound to the VM.

100 114 116 114 114 116 100 114 114 116 100 114 118 104 102 114 118 114 114 116 114 110 114 102 As noted above, the processing systemis generally configured to implement a confidential computing environment and, in particular, to execute a plurality of VMs, also referred to as guests, and a VMM (hypervisor), also referred to as a host, to manage the execution of the plurality of VMs. Because the different VMs, and at least in some cases the VMM, are owned by different entities, the processing systemimplements security features to protect the data of a given VMfrom access by other software, such as by another VMor by the VMM. For example, the processing systemimplements data security for the VMsby implementing a secure regionof the memorythat stores encrypted data. In particular, the processoris configured to encrypt specified data for each VMaccording to a corresponding private cryptographic key and to store the encrypted data at the secure region. Because the data is encrypted, the data for one VMis protected from unauthorized access by other VMsand by the VMM. In at least some implementations, cryptographic keys for the VMsare managed by the security module, and data encryption and decryption for the VMsis executed by a dedicated hardware encryption/decryption module (not shown) at a memory controller (not shown) of the processor.

100 120 120 100 114 120 116 114 110 120 100 122 122 106 112 122 106 In at least some implementations, the confidential computing environment of the processing systemprovides integrity guarantees by implementing a Reverse Map Table (RMP). The RMPis a single data structure shared across the systemand comprises one entry for every given memory page (e.g., 4k page) of memory that can be used by VMs. The RMPtracks the owner for each page of memory. Pages of memory can be owned by the VMM, a specific VM, or by the security module. Access to memory is controlled so only the owner of that page can write it. The RMP, in at least some implementations, is used in conjunction with standard page tables to enforce memory restrictions and page access rights. In at least some implements, the processing systemalso implements a Secure Device Table (SDT)that encodes device interface VM bindings and security attributes. The SDT, in at least some implementations, is a store of the security attributes of the I/O devices. The IOMMUexamines the SDTwhen there is traffic from or to the I/O deviceto make a security policy decision on whether the access is allowed or not allowed.

106 104 114 104 104 112 106 112 102 112 102 112 106 104 112 104 104 An I/O device, in at least some implementations, accesses memoryassigned to a VMby generating direct memory access (DMA) requests to read data from the memory, write data to the memory, or a combination thereof. The IOMMUis configured to handle the DMA requests issued by I/O devices. For example, to enhance processing efficiency, the IOMMUis generally configured to perform specified memory access operations on behalf of the processor—that is, to perform memory access operations using dedicated hardware of the IOMMU, and without requiring management of the memory access operations by the processor. In particular, the IOMMUincludes dedicated hardware to perform DMA operations. In some implementations, each DMA request issued by an I/O deviceincludes a descriptor indicating the virtual addresses of the data to be accessed—that is, the virtual address of the data to be read, the virtual address where data is to be written, or both. These virtual addresses indicate the region of the memorythat is targeted by the DMA request. The IOMMUis generally configured to translate the virtual addresses indicated by a DMA request to physical addresses of the memoryand to interact with the memoryto carry out the one or more operations (read operations, write operations or a combination thereof) indicated by the DMA request.

108 106 114 108 106 106 108 106 112 In at least some implementations, the processor coreaccesses an I/O deviceby issuing MMIO requests associated with a particular executing VM. Each MMIO request identifies a memory address from which data is to be read, a memory address to which data is to be written, or a combination thereof. For example, in some cases, the processor coreprograms a particular register of an I/O deviceby issuing an MMIO request to write data to a memory address associated with the register. By using memory addresses to provide information to, or retrieve information from, an I/O device, the processor corecan interact with the I/O deviceusing a relatively simple set of access commands and by leveraging at least some hardware used to access system memory, thereby improving the overall efficiency of the processor core. To enhance processing efficiency, the IOMMUassists in executing the MMIO requests, such as by performing virtual-to-physical address translations for the MMIO requests.

106 114 106 134 134 1 134 2 134 106 114 134 The confidential computing environment further implements I/O virtualization, such that the I/O devicesare virtualized and shared across multiple VMs. One example, of I/O virtualization implemented by the confidential computing environment is SIOV. In some implementations, one or more I/O devicesare a physical I/O virtualization-capable device implementing one or more device interfaces(illustrated as device interface-and device interface-). Each device interfaceallows the I/O deviceto be virtualized as a different virtual I/O device for each VM. In at least some implementations, the device interfacesare assignable device interfaces (ADIs), which form the unit of assignment and isolation to form virtual devices.

114 134 116 134 134 114 134 114 134 124 108 124 134 124 After a VMhas been assigned to a device interfaceby the VMM, a software process/thread of the VM submits work requests to the device interfaceusing one or more techniques. In one example, a process submits work requests through a shared work queue (SWQ) of the device interface, which are interfaces that allow multiple VMsto submit work requests to the same device interface. In at least some implementations, a process of a VMsubmits work requests to a device interfaceby sending an enqueue command, such as ENQCMD or ENQCMDS, to the processor core. The enqueue command, in at least some implementations, is an instruction that atomically submits a work descriptor to a device interface. The enqueue commandincludes, for example, virtual addresses of all parameters, virtual address of a completion record, and the PASID of the VM process that is submitting the work descriptor.

114 114 116 116 114 114 116 126 116 114 114 A PASID is a unique identifier that isolates the process address space used by a VMand links a process's accesses to its view of and access rights to memory. A PASID is used to distinguish upstream memory transactions performed for different devices and to convey the address space targeted by the transaction. VMsoperate using guest PASIDs while the VMM(including underlying hardware) operates using host PASIDs. In at least some implementations, the VMMassigns PASIDs to a VMfrom a global pool of available PASIDs and the VMassigns multiple PASIDs to its processes. The VMMvirtualizes the PASIDs by maintaining a mapping of the guest PASIDs and host PASIDs in one or more data structures, such as PASID mapping tables. That is, the VMMtransparently maps the PASIDs assigned by the VMto real PASIDs to give the VMthe view that it owns the entire PASID space.

2 FIG. 200 200 204 202 210 210 1 210 2 212 114 210 214 214 1 214 2 206 202 216 216 1 216 2 214 216 218 218 1 218 2 208 202 218 220 220 1 220 2 202 shows one example of a PASID mapping table configurationapplicable to the techniques described herein. It should be understood that other mapping table configurations are applicable as well. In the mapping table configuration, a first portionof the guest PASIDincludes a PASID directory indicator. The PASID directory indicator identifies a PASID directory pointer(illustrated as PASID directory pointer 1-and PASID directory pointer N-) in a memory data structureassociated with the corresponding VM. The PASID directory pointerpoints to a PASID directory(illustrated as PASID directory 1-and PASID directory N-). A second portionof the guest PASIDidentifies a specified entry(illustrated as entry-and entry-) in the PASID directory. The specified entrypoints to a specified PASID table(illustrated as PASID Table 1-and PASID Table M-). A third portionof the guest PASIDidentifies a specified entry in the PASID tablecomprising the corresponding host PASID(illustrated as Host PASID-and Host PASID-) of the guest PASID.

1 FIG. 134 114 108 124 124 134 108 126 108 128 134 128 128 108 128 134 130 Referring again to, each task submitted to a device interfaceby a process in the VMis associated with a guest PASID that is translated into a corresponding host PASID. This translation task is performed by the CPU corefor enqueue commands. For example, when a VM process invokes an enqueue commandfor submitting a work request descriptor to the device interfaceby writing to the registers of an SWQ, the processor coreuses the PASID mapping table(s)to automatically translate the guest PASID associated with the work request into a host PASID. The core processorthen uses a type of memory access over PCIe, referred to as a deferrable memory write (DMWr), to place the work request into the SWQ of the device interface. A DMWris a write that can temporarily fail due to unavailability of the underlying resource. The DMWrincludes information such as the host PASID identified based on the translation process and the work request sent by the VM process. In at least some implementations, the CPU coresends the DMWrto the device interfacethrough a PCIe controller.

116 106 100 116 114 116 108 132 132 114 132 108 124 116 110 132 As described above, the VMMis responsible for mapping guest PASIDs to host PASIDs and mapping host PASIDs to guest contexts within an I/O device. Therefore, a malicious or corrupted VMM potentially has the opportunity maliciously set/change a PASID and gain access to an isolation domain in the virtualized computing environment. As such, the processing systemimplements one or more security mechanisms such that allow the VMMto indirectly allocate PASIDs for a VMwhile not allowing the VMMarbitrary authority to change the mapping. For example, the processor coremaintains and secures one or more data structures, referred to herein as a PASID reverse map table (PMP)that is global to the system that is indexed by the host PASID. In at least some implementations, the PMPcomprises one entry for each guest PASID assigned by a VM. The PMPincludes per-host PASID security attributes that are checked by the processor coreupon receiving an enqueue commandfrom a VM process to ensure that the VMMhas not unexpectedly changed the PASID mapping. In at least some embodiments, the security moduleinitializes the PMP.

3 FIG. 132 132 301 132 302 304 306 308 310 302 301 114 302 114 304 114 301 306 301 308 108 132 301 132 301 308 301 308 301 310 114 301 114 shows one example of the PMPin accordance with some implementations. In the depicted example, the PMPincludes a plurality of entries, wherein each entry is assigned to a different host PASID. Each entry of the PMPincludes a plurality of fields, including an Assigned field, a Guest ID field, a Guest PASID field, a Lock field, a Validated field, and the like. The Assigned fieldstores a bit (or other information) that indicates whether the host PASID associated with the PMP entryhas been assigned (or has not been assigned) to a VM. For example, if the bit is set in the Assigned field, this indicates the host PASID has been assigned to a VM. The Guest ID fieldstores an identifier, such as an address space identifier (ASID), of the VMthat has been assigned to the host PASID associated with the PMP entry. The Guest PASID fieldstores the guest PASID that should translate to the host PASID associated with PMP entry. The Lock fieldstores a bit (or other information) that is used to coordinate multiple hardware threads of the processor corewhen concurrently accessing the PMP. If there are multiple hardware threads and one is updating an entryof the PMPand the other threads are trying to access the same entry, the Lock fieldindicates to the threads that owns the entry. For example, a thread will attempt to atomically set the bit of the Lock fieldwhen writing to the entry. If the thread successfully sets the bit, the thread knows that it owns the entry and can continue accessing the entry. The thread will clear the bit after it has completed its operations. The Validated fieldstores a bit (or other information) indicating that the VMhas previously validated that the host PASID associated with the entryis assigned to the VM, as described in greater detail below.

4 FIG. 6 FIG. 4 FIG. 4 FIG. 100 132 114 116 114 114 116 126 116 401 301 132 116 401 402 108 108 402 301 132 402 301 302 114 304 114 306 310 114 301 310 301 301 114 totogether illustrate an example of the processing systemperforming secure management of PASID mapping using the PMPto protect VMsfrom unexpected changes to the PASID mapping in accordance with some implementations. In the illustrated example, a VMMinitially assigns a host PASID to a VMand the VMassigns a guest PASID to one or more of its processes. The VMMsets the entries in the PASID mapping table(s)using one or more techniques (e.g., memory writes) to map the guest PASIDs to host PASIDs. As shown in, the VMMthen invokes a PMP update processto update an entryin the PMPfor a particular host PASID. In at least some implementations, the VMMperforms the PMP update processby sending an instruction, such as a PMPUPDATE instruction, to the processor core. The processor corethen executes the instructionto update the entryin the PMP. The instructionincludes information/parameters to update one or more fields of the entry. For example, the Assigned fieldis updated to indicate that the associated host PASID has been assigned to a VM, the Guest ID fieldis updated to include the guest ID of the VMthat owns the associated host PASID, and the Guest PASID fieldis updated with the guest PASID that should translate to the associated host PASID. The PMP update process also clears/resets the bit stored in the Validated field, which indicates that the VMMhas changed the information maintained by that entry. For example,shows that the Validated fieldof the PMP entryhas a value of “0”, which indicates that the contents of the entryhave been changed and have not been validated by a VM.

114 134 114 501 114 502 108 108 502 502 502 126 200 502 204 210 212 114 502 206 216 214 218 502 208 218 502 132 301 301 132 502 301 502 302 304 114 501 114 501 502 310 301 301 114 310 301 301 114 5 FIG. 2 FIG. 5 FIG. In at least some implementations, when a VMintends to access a device interfaceusing a specified guest PASID, the VMperforms a PMP validation processto validate the mapping of that guest PASID as illustrated in. For example, the VMsends an instruction or request, such as a PMPVALIDATE instruction, to the processor core. The processor corethen executes the instruction. The instructionincludes one or more parameters, such as the guest PASID. The instructionuses the PASID mapping tablesto translate the guest PASID to its host PASID. For example, referring to the mapping table configurationof, the instructionuses the PASID directory indicator in the first portionof the guest PASID to identify a PASID directory pointerfrom the memory data structureassociated with the VM. Then, the instructionuses the second portionof the guest PASID to identify a particular entryin the associated PASID directoryfor locating the corresponding PASID table. The instructionuses the third portionof the guest PASID to locate the entry in the PASID tablecomprising the corresponding host PASID of the guest PASID. The host PASID is used by the instructionas an index into the PMPto identify the entryassociated with the host PASID. After the entryin the PMPhas been identified, the instructionchecks one or more fields of the entry. For example, the instructionchecks the Assigned fieldto determine if the host PASID has been assigned and also checks the Guest ID fieldto determine if the VMperforming the PMP validation processis assigned to the host PASID. If the host PASID has been assigned and is assigned to the VMperforming the PMP validation process, the instructionsets the bit in the Validated fieldof the entryto indicate that the contents of the entryhave been explicitly verified by the VM. For example,shows that the Validated fieldof the PMP entryhas a value of “1”, which indicates that the contents of the entryhave been validated by the VM.

114 134 114 124 108 134 124 134 124 108 124 124 126 501 6 FIG. 1 FIG. When a process of the VMwants to access the device interfaceassigned to the VM, the process issues an enqueue commandto the processor coreas illustrated in. The enqueue command is generated by the process to place a work request in the SWQ of the device interfaceas described above with respect to. The enqueue commandincludes, for example, virtual addresses of all parameters, virtual address of a completion record, and the guest PASID of the VM process that is submitting the work to the device interface. In other embodiments, the enqueue commandobtains the guest PASID by reading an MSR programmed with the guest PASID. The processor corereceives the enqueue commandand, using the guest PASID included within the enqueue command, translates the guest PASID into its host PASID using the PASID mapping table(s)similar to the translation process described above with respect to the PMP validation process.

124 108 601 108 703 702 124 720 108 720 132 701 720 108 601 701 108 306 701 702 304 701 114 114 124 116 126 108 302 720 114 310 301 114 124 108 116 114 301 124 114 116 132 402 124 108 128 114 134 501 601 114 7 FIG. 7 FIG. As part of executing the enqueue command, the processor coreperforms a PMP checkon the PASID translation as illustrated in. For example,shows that processor coreperforms a translation processto translate the guest PASIDincluded within the enqueue commandinto its host PASID. The processor coreuses the host PASIDas an index into the PMPto identify the PMP entrycorresponding to the host PASID. The processor corethen performs the PMP checkto determine if the entrysatisfies one or more conditions. For example, the processor coredetermines if the Guest PASID fieldof the entryincludes a guest PASID that matches the translated guest PASIDand the Guest ID fieldof the entryincludes the identifier of the accessing VM(i.e., the VMthat issued the enqueue command). This reverse mapping check ensures that the VMMdid not change the PASID mapping tables. In at least some implementations, the processor corealso checks if the Assigned fieldindicates that the host PASIDhas been assigned to a VM, the Validated fieldindicates that the current contents of the entryhave been previously validated by the VMassociated with the enqueue command, or a combination thereof. If any of these conditions do not hold true, the PMP check fails and the processor coredetermines that the VMMhas unexpectedly changed the PASID mapping after the VMpreviously validated the contents of the entry. The enqueue commandwill then exit the VMand the VMMis expected to recover by updating the PMPusing the PMP update instructiondescribed above. However, if the PMP check conditions hold true, the enqueue commandproceeds and the processor coreissues a DMWrfor placing a work request submitted by the process of the VMinto the SWQ of the device interface. As such, the PMP validationand PMP checkprocesses ensure that the processes of the VMdo not act on unexpected or malicious PASID mappings.

8 FIG. 9 FIG. 1 FIG. 1 FIG. 800 800 100 800 802 116 114 116 114 804 114 806 116 116 126 116 116 114 114 andtogether illustrate a flow diagram of a methodof securely managing PASID mapping in a confidential computing environment implementing input/output virtualization in accordance with some implementations. For purposes of description, the methodis described with respect to an example implementation at the processing systemof, but it will be appreciated that, in other implementations, the methodis implemented at processing systems having different configurations. At block, the VMMinitially assigns a host PASID to a VM. For example, the VMMassigns a host PASID to a VMfrom a global pool of available PASIDs. At block, the VMassigns a guest PASID to one or more of its processes. At block, the VMMstores guest PASID and host PASID mapping information. For example, the VMMsets the entries in the PASID mapping table(s)as described above with respect to. Maintaining the mapping of the PASIDs allows the VMMto virtualize the PASIDs. That is, the VMMtransparently maps the PASIDs assigned by the VMto real PASIDs to give the VMthe view that it owns the entire PASID space.

808 116 401 506 116 402 302 304 306 402 310 810 114 134 502 502 126 502 132 301 301 132 502 301 502 301 114 4 FIG. 5 FIG. At block, the VMMperforms the PMP update processdescribed above with respect tobased on the mapping performed at block. For example, the VMMexecutes a PMP update instructionthat updates the Assigned field, the Guest ID field, and the Guest PASID field. The PMP update instructionalso clears the validated bit in the Validated field. At block, a process of the VMintends to access a device interfaceusing an assigned guest PASID and executes a PMP validate instruction (or request). The PMP validate instructionuses the PASID mapping tablesto translate the guest PASID to its host PASID as described above with respect to. The PMP validate instructionuses the host PASID as an index into the PMPto identify the entryassociated with the host PASID. After the entryin the PMPhas been identified, the instructionchecks one or more fields of the entry. For example, the PMP validate instructionconfirms the entry indicates that the host PASID associated with the entryhas been assigned to the guest ID of the VM.

812 124 134 124 134 814 108 124 816 108 124 108 132 601 818 826 818 108 132 301 820 108 302 301 114 114 828 108 116 108 134 114 116 401 822 108 114 304 301 114 304 828 108 116 824 108 306 301 306 828 108 116 826 108 301 114 301 108 116 301 114 501 810 828 108 116 301 114 128 830 114 134 128 108 601 820 826 1 FIG. 6 FIG. 7 FIG. At block, the process issues an enqueue commandto access the device interface. For example, the enqueue commandattempts to place a work request in the SWQ of the device interface, as described above with respect to. At block, the processor corereceives the enqueue command. At block, the processor coretranslates the guest PASID included in the enqueue commandto its host PASID as described above with respect toand. The processor coreuses the host PASID as an index into the PMPfor performing a PMP check processat blocksto. For example, at block, the processor coreuses the host PASID as an index into the PMPto identify the entrycorresponding to the host PASID. At block, the processor coredetermines if the Assigned fieldof the entryindicates that the host PASID has been assigned to a VM. If the host PASID has not been assigned to a VM, the process flows to blockand the processor coresends an error notification to the VMM. Stated differently, the processor coreprevents access to the device interfaceby the VM. The VMMis then expected to perform the PMP update processto correct the error. Otherwise, the process flows to blockand the processor coredetermines if the Guest ID of the VMmatches the Guest ID included in the Guest ID fieldof the entry. If the Guest ID of the VMdoes not match the Guest ID included the Guest ID field, the process flows to blockand the processor coresends an error notification to the VMM. Otherwise, the process flows to blockand the processor coredetermines if the translated guest PASID matches the guest PASID included in the Guest PASID fieldof the entry. If the translated guest PASID does not match the guest PASID included in the Guest PASID field, the process flows to blockand the processor coresends an error notification to the VMM. Otherwise, the process flows to blockand the processor coredetermines if the current contents of the entryhave been previously validated by the VM. If contents of the entryhave not been previously validated, the processor coredetermines that the VMMhas changed the contents of the entryafter the VMperformed the PMP validation processat block. The process then flows to blockand the processor coresends an error notification to the VMM. However, if the current contents of the entryhave been previously validated by the VM, the processor issues a DMWrat blockto place the work request submitted by the process of the VMinto a SWQ of the device interface. The DMWrincludes information such as the host PASID identified based on the translation process and the work request submitted by the process. It should be understood that, in other implementations, the processor coreperforms the PMP checkusing a different arrangement of blocksto.

In some implementations, certain aspects of the techniques described above may be implemented by one or more processors of a processing system executing software. The software includes one or more sets of executable instructions stored or otherwise tangibly embodied on a non-transitory computer readable storage medium. The software can include the instructions and certain data that, when executed by the one or more processors, manipulate the one or more processors to perform one or more aspects of the techniques described above. The non-transitory computer readable storage medium can include, for example, a magnetic or optical disk storage device, solid state storage devices such as Flash memory, a cache, random access memory (RAM) or other non-volatile memory device or devices, and the like. The executable instructions stored on the non-transitory computer readable storage medium may be in source code, assembly language code, object code, or other instruction format that is interpreted or otherwise executable by one or more processors.

Note that not all of the activities or elements described above in the general description are required, that a portion of a specific activity or device may not be required, and that one or more further activities may be performed, or elements included, in addition to those described. Still further, the order in which activities are listed are not necessarily the order in which they are performed. Also, the concepts have been described with reference to specific implementations However, one of ordinary skill in the art appreciates that various modifications and changes can be made without departing from the scope of the present disclosure as set forth in the claims below Accordingly, the specification and figures are to be regarded in an illustrative rather than a restrictive sense, and all such modifications are intended to be included within the scope of the present disclosure.

Benefits, other advantages, and solutions to problems have been described above with regard to specific implementations. However, the benefits, advantages, solutions to problems, and any feature(s) that may cause any benefit, advantage, or solution to occur or become more pronounced are not to be construed as a critical, required, or essential feature of any or all the claims. Moreover, the particular implementations disclosed above are illustrative only, as the disclosed subject matter may be modified and practiced in different but equivalent manners apparent to those skilled in the art having the benefit of the teachings herein. No limitations are intended to the details of construction or design herein shown, other than as described in the claims below. It is therefore evident that the particular implementations disclosed above may be altered or modified and all such variations are considered within the scope of the disclosed subject matter. Accordingly, the protection sought herein is as set forth in the claims below.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

March 16, 2023

Publication Date

August 18, 2026

Inventors

Jeremy W. Powell
David Kaplan

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Secure mapping of process address space identifiers for computing environments implementing input/output virtualization” (US-12710974-B2). https://patentable.app/patents/US-12710974-B2

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.